Port 995: POP3 over implicit TLS
TCP 995 is the default port for POP3 over implicit TLS, where TLS starts as soon as the connection opens. Mail clients use POP3 to download messages from a mail access server. RFC 8314 updated the 995 registration and recommends implicit TLS over cleartext POP3 on port 110.
Port Details
Security Exposure
POP3 servers accept mailbox passwords, so an internet-facing 995 listener is exposed to password guessing and credential reuse. Microsoft, which removed Basic authentication for POP and IMAP in Exchange Online, notes that Basic authentication makes credentials easier to capture and MFA harder to enforce.
Hardening
- +Disable POP3 entirely if mail clients use IMAP or vendor protocols.
- +Turn off cleartext POP3 on port 110 and support TLS 1.2 or later on 995, as RFC 8314 requires of mail access servers.
- +Use modern authentication and MFA where the mail platform supports it.
- +Rate-limit failed logins per account and per source address.
Monitoring
Log POP3 authentication failures and successful logins with source address, and alert on spray patterns across many accounts.
Tools for Auditing and Monitoring POP3S
Hydra
Open SourceParallelized network login auditing tool that tests dozens of remote authentication protocols including SSH, SMB, RDP, HTTP, and database services.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Wazuh
Free / CommercialOpen-source SIEM and XDR platform providing endpoint monitoring, log analysis, file integrity checks, and threat detection.
Related Tool Categories
Frequently Asked Questions
What is the difference between port 110 and 995?→
Port 110 is plain POP3. Port 995 is POP3 over implicit TLS, registered as pop3s; RFC 8314 updated that registration.
Should POP3 be disabled?→
Where no clients need it, disabling it removes an authentication endpoint. If it is kept, RFC 8314 requires mail access servers to support TLS 1.2 or later and recommends deprecating cleartext access.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 995 is not guaranteed to be POP3S. Exploited-in-the-wild data from the CISA KEV catalog (CC0).